Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Dashboard TO DO ListAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1. | |
| Aplazada | Media (4.4) | 0.36% | — | Announce From THE DashboardAI | 4/4/2024 | 17/6/2026 | The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco Nexus Dashboard Fabric Controller | 3/4/2024 | 17/6/2026 | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through… | |
| Analizada | Media (4.3) | 0.38% | — | Cisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user… | |
| Analizada | Media (4.3) | 0.41% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A… | |
| Analizada | Media (6) | 0.17% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this… | |
| Analizada | Alta (8.8) | 0.26% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the… | |
| Aplazada | Media (6.5) | 0.36% | — | Buffercode Frontend DashboardAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1. | |
| Aplazada | Media (5.4) | 0.46% | — | Sharethis Dashboard FOR Google AnalyticsAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4. | |
| Analizada | Media (5.4) | 0.81% | 💥 Exploit | Bowo System Dashboard | 20/3/2024 | 17/6/2026 | The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.22% | — | Automattic Crowdsignal Dashboard | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Media (4.3) | 0.30% | — | Mainwp Dashboard | 13/3/2024 | 17/6/2026 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.40% | — | Jeroensormani WP Dashboard Notes | 27/2/2024 | 17/6/2026 | The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and… | |
| Analizada | Alta (8.4) | 0.23% | — | TD Advanced Dashboard | 21/2/2024 | 17/6/2026 | The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information. | |
| Modificada | Media (6.1) | 0.35% | — | Automattic Crowdsignal Dashboard | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Stimulsoft Dashboards.php | 6/2/2024 | 9/7/2026 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. | |
| Modificada | Media (6.1) | 0.83% | 💥 PoC | Stimulsoft Dashboard.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component. | |
| Modificada | Media (5.4) | 0.76% | 💥 PoC | Stimulsoft Dashboards.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |
| Modificada | Alta (8.8) | 0.19% | — | Custom Dashboard Widgets Project Custom Dashboard Widgets | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1. | |
| Modificada | Alta (8.2) | 0.46% | — | Flatlogic React Dashboard | 30/1/2024 | 17/6/2026 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. | |
| Modificada | Media (4.8) | 0.40% | — | Davidvongries Ultimate Dashboard | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11. | |
| Modificada | Media (4.9) | 0.55% | — | Mainwp Dashboard | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3. | |
| Modificada | Media (4.8) | 0.39% | — | Plugin-planet Dashboard Widget Suite | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1. | |
| Modificada | Media (6.1) | 0.40% | — | Deconf Clicky Analytics Dashboard | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. | |
| Modificada | Crítica (9.8) | 0.71% | — | Joomcode Jcdashboard | 14/12/2023 | 17/6/2026 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. |